Live data from Hacker News

Attacking Tor: How the NSA targets users' online anonymity

theguardian.com

31–40 of 184 posts

Re: Attacking Tor: How the NSA targets users' online anonymity

#31
post #17
post #2

At least according the the slides, Tor appears to be safe for the most part. Which is good.

[deleted]

Actually the slidedeck states that Tor Browser Bundle defeats some of the attacks they use that plain Tor+Vidalia is vulnerable to.

And if you're referring to the previous Freedom Hosting attack, that only affected users of TBB on Windows who had ignored "Security Update Available" messages for over a month.

Re: Attacking Tor: How the NSA targets users' online anonymity

#33
post #7

Metacommentary: I've taken a jaundiced view of "liberation tech" efforts in the past and this is as good an illustration as any of why. Among "amateur" libtech projects, Tor is about as good as you get --- an active community, extremely widespread use, technical people with their heads screwed on right and as much humility as you can reasonably expect of people whose projects are (candidly) intended to thwart world g…

What chance does a ragtag team of people from various backgrounds working part time on a open source project have against a determined enemy with billions in funding and hordes of PHDs working full time with single goal of violating privacy of netizens.

A better chance than one would think from that phrasing, as there are a lot of highly motivated and intelligent people working on privacy tech.

Re: Attacking Tor: How the NSA targets users' online anonymity

#34
post #7

Metacommentary: I've taken a jaundiced view of "liberation tech" efforts in the past and this is as good an illustration as any of why. Among "amateur" libtech projects, Tor is about as good as you get --- an active community, extremely widespread use, technical people with their heads screwed on right and as much humility as you can reasonably expect of people whose projects are (candidly) intended to thwart world g…

I didn't read it that way at all, in fact, it sounds like Tor is sufficiently robust that a good number of NSA employees were tasked with finding exploits. In terms of the exploits found, it looks like all were against the browser. Tor is a well-designed and robust anonymity tool, and successfully attacking it is difficult. The NSA attacks we found individually target Tor users by exploiting vulnerabilities in their…

Tor enabled them to filter down Internet traffic to a subset, and then they simply violated the security premise behind real-world Tor usage (that the rest of the stack was secure) to pierce the veil completely.

I'm not indicting Tor. The opposite. But in Iran, China, or Belarus, you don't get to call a foul ball when your libtech stack breaks somewhere you weren't working on.

And again, my concern isn't Tor, but the (far more amateurish) things people come up with as new Tor alternatives to e.g. "circumvent the great firewall".

The principle I'm trying to communicate is that there's a degree of chauvinism implicit in amateur libtech --- that despite the billions of dollars any real country can leverage against Internet privacy, indie developers have a fighting chance against Iran, because after all they're just a tinpot dictatorship.

The other more general principle I try to communicate is that it doesn't matter how nice, or even how necessary, any given bit of security technology is. What matters is the engineering: will it work as deployed. Not having a better answer doesn't change the engineering fact of whether the best current solution is viable.

Re: Attacking Tor: How the NSA targets users' online anonymity

#35

Sounds like, if you're going to do something very sensitive on tor, you need to: - always have an update to date version of tor bundle! - compile the bundle yourself from source - run it virtually, and always roll back to a clean snapshot (before installing it tor) when done - if possible use from a network that is not your own (open wifi, public wifi, etc.) - spoof your mac address - do not run JS, Java applets, etc…

Yeah, I was wondering if a virtual machine is safe from malicious attacks, though. Can anyone comment on the feasibility of this method as fail-safe?

Re: Attacking Tor: How the NSA targets users' online anonymity

#36
post #7

Metacommentary: I've taken a jaundiced view of "liberation tech" efforts in the past and this is as good an illustration as any of why. Among "amateur" libtech projects, Tor is about as good as you get --- an active community, extremely widespread use, technical people with their heads screwed on right and as much humility as you can reasonably expect of people whose projects are (candidly) intended to thwart world g…

What chance does a ragtag team of people from various backgrounds working part time on a open source project have against a determined enemy with billions in funding and hordes of PHDs working full time with single goal of violating privacy of netizens.

That's entirely not the point. Even with 1000x the amount of funding, TOR would still be theoretically proven to be insecure. Only physicially secure hardware (including cables and routers) stands a chance against side-channel traffic analysis.

Re: Attacking Tor: How the NSA targets users' online anonymity

#37
One heartening aspect of the Snowden revelations as a whole is that they have pretty much just confirmed that the things we thought were strong (public crypto research, tor) are in fact strong and the things that we thought were iffy are in fact iffy(Certificate Authorities, Unvetted Crypto, Cloud Services, The Wires, Implementations). This bodes well for the prospect of navigating out of this whole mess successfully since on the whole we seem to have good instincts about what is trustworthy and what is untrustworthy. I think that it actually has tended to clarify thinking about security so that fewer and fewer engineers are able to delude themselves into trusting something that they know deep down is really untrustworthy.

Re: Attacking Tor: How the NSA targets users' online anonymity

#38

Sure these folks are smart and have all sorts of powerful weapons; what are the odds that someone out there could successfully repurpose some of these weapons? What is the likelihood that vulnerabilities exist in the NSA's systems? We can never know since it's all secret. If someone does take over these systems we wouldn't know that either.

Historically, different nations' intelligence agencies have often infiltrated each other. I'm sure someone will eventually gain access to the NSA's weapons, but I think they would be more likely to steal details to add to their own systems than "repurpose" the NSA's.

Re: Attacking Tor: How the NSA targets users' online anonymity

#39
post #29

Earlier quoted context omitted.

I think that's a pretty serious exaggeration. Designing tools to let you spy on Tor traffic has to be in a separate category from designing bombs that could kill millions. Besides, are there no ends that could justify these means? I think the means are altogether reasonable given the ends. Put aside whether you think the NSA is genuinely pursuing its national security mission: If it were, wouldn't it make perfect sen…

Attacking Tor by passive analysis is one thing. Installing spyware, creating a botnet, and making the infection process quick and easy is another. There might be some justification for the former. The latter is too risky.

It's not a "Manhattan Project" if it's within the capabilities of any decent-sized organized crime syndicate. People here have short memories. In the 1990s, teenaged hackers owned up the backbone.

Re: Attacking Tor: How the NSA targets users' online anonymity

#40
post #29

Earlier quoted context omitted.

I think that's a pretty serious exaggeration. Designing tools to let you spy on Tor traffic has to be in a separate category from designing bombs that could kill millions. Besides, are there no ends that could justify these means? I think the means are altogether reasonable given the ends. Put aside whether you think the NSA is genuinely pursuing its national security mission: If it were, wouldn't it make perfect sen…

Attacking Tor by passive analysis is one thing. Installing spyware, creating a botnet, and making the infection process quick and easy is another. There might be some justification for the former. The latter is too risky.

Actually, I'd say there is more justification for the later. Passive analysis nails everyone. It's a scary capability to have.

Malware is a fundamentally targeted endeavor since known exploits get patched.

The question of course, is are the targets legitimate?

Post reply on HN